Information Disclosure Vulnerability in SiYuan by SiYuan Tech
CVE-2026-72792
6.9MEDIUM
What is CVE-2026-72792?
The SiYuan application prior to version 3.7.4 has an information disclosure vulnerability affecting the /api/tag/getTag endpoint. This flaw allows unauthenticated users to access sensitive tag labels and occurrence counts from documents that should be password-protected. By exploiting this vulnerability, attackers can enumerate vocabulary and internal terminology from secured documents, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
